Frequently Asked Questions

This section provides answers to common questions about Sectona PAM Cloud, including deployment, architecture, security, networking, integrations, licensing, and operational best practices. Refer to this section to quickly find information and better understand the platform's capabilities and supported configurations.

Who is an ideal Sectona PAM Cloud customer?

Organizations evaluating PAM as a SaaS offering are ideal Sectona Cloud customers.

Is the SaaS platform penetration tested regularly, and can we see the reports?

Yes. Sectona Cloud undergoes annual third-party penetration testing. Reports are available to enterprise customers under NDA as part of the vendor security assessment process.

Who manages SSL certificates and domain configuration in SaaS mode?

Sectona manages all SSL/TLS certificates for the Sectona Cloud environment, including renewals and domain configuration. Customers receive a dedicated subdomain (e.g., rocklabs.sectona.cloud) out of the box. Custom naming preferences can be requested during implementation.

Can an existing Sectona On-premises customer be migrated to Sectona Cloud? If yes, with what data?

Yes. Existing customer data can be migrated to the SaaS platform, including:

  • All PAM configurations

  • Session metadata

  • Video recording up to 15 days (subject to additional charges, if any).

Is offline or air-gapped operation supported in SaaS mode?

No. Sectona Cloud requires continuous internet connectivity to function. For air-gapped or fully isolated environments, the on-premises PAM edition is the recommended deployment option.

Can we get direct access to the underlying database or application servers of our cloud instance?

No. Direct infrastructure access to the underlying database or application servers is not permitted in the SaaS model.

How will product updates and patches be handled?

Sectona will notify customers in advance about the scheduled maintenance window for updates and patch deployments.

Is customer data isolated in the SaaS platform?

Yes. Every customer gets a dedicated VPC instance with strict network isolation, ensuring there is no cross-tenant data access.

What is the typical POC duration?

A standard proof of concept (POC) is available for 10 calendar days and covers:

  • Onboarding

  • Use-case validation

  • Evaluation sign-off

Can Sectona PAM Cloud connect to on-premises targets?

Yes. The Sectona RNA Connector securely bridges cloud and on-premises targets through an outbound TLS tunnel.

Is the solution compliant with SOC 2 / ISO 27001?

Yes. Sectona PAM - Cloud is currently in the process of:

  • SOC 2 Type-II certification

  • ISO 27001 compliance

Can we bring our own IdP for SSO?

Absolutely. Sectona Cloud supports:

  • SAML 2.0

  • Azure AD

  • Okta

  • Any SAML-compliant Identity Provider (IdP)

What MFA options are supported?

Supported Multi-Factor Authentication (MFA) methods include:

  • TOTP

  • SMS

  • Email

  • Google Authenticator

  • Microsoft Authenticator

  • Duo Security

  • RADIUS-based MFA

What happens to our data if we decide to exit Sectona Cloud?

Customers can export reports and other data in standard formats within the active license validity period.

Where is the customer’s PAM instance hosted?

Customer PAM instances are shown in the table below:

Region

Primary (Production)

Disaster Recovery (DR)

South Asia (SA)

Mumbai

Hyderabad

Middle East (ME)

Dubai

NA

United Kingdom (UK)

London

Ireland

European Union (EU)

Frankfurt (Germany)

Ireland

East Asia (EA)

Singapore

NA